SBOM vs AIBOM vs MLBOM
Three bills of materials, often confused. A Software Bill of Materials (SBOM) lists your software components and licenses. A Machine Learning Bill of Materials (MLBOM) lists a single modelβs composition. An AI Bill of Materials (AIBOM) is the superset that wraps both. Compare them side by side, then generate your own.
| Attribute | SBOM | AIBOM | MLBOM |
|---|---|---|---|
| Full name | Software Bill of Materials | AI Bill of Materials | Machine Learning Bill of Materials |
| What it inventories | Every software component and dependency in a build, each with version and license. | Everything an AI system is built from: the software, plus every model, dataset and their licenses and provenance. | The composition of a machine-learning model: architecture, training datasets, hyperparameters and weight provenance. |
| Typical formats | SPDX, CycloneDX | CycloneDX (ML extensions), SPDX 3.0 AI profile | CycloneDX ML-BOM |
| What drives it | US EO 14028, EU Cyber Resilience Act, customer and procurement requirements. | EU AI Act technical-documentation duties for high-risk systems; enterprise AI governance. | Model risk management, model cards, and AI governance that needs training-data lineage. |
| What it famously misses | The model weights and the training data β the parts that make an AI system an AI system. | Little, by design β but only as good as the model and dataset metadata you can actually obtain. | The surrounding application software and its ordinary dependencies. |
| Best when | You ship or consume software and need to answer "are we exposed to this CVE?" fast. | You build or deploy AI features and must evidence what models and data are inside them. | You train or fine-tune models and need lineage for a specific model artifact. |
Tap a column to highlight one bill of materials. AIBOM is the superset: it contains the software of an SBOM and the model lineage of an MLBOM.
Which do I need?
Ship software, no AI: an SBOM. Ship software with AI features: an AIBOM (it includes the SBOM). Train or fine-tune models: keep an MLBOM per model and reference it from your AIBOM.
The three in five lines
- An SBOM lists software components and licenses. An MLBOM lists a modelβs composition β architecture, training data, weights. An AIBOM is the superset: the software plus every model and dataset.
- SBOMs use SPDX or CycloneDX. MLBOMs use the CycloneDX ML-BOM. AIBOMs use CycloneDX ML extensions or the SPDX 3.0 AI profile.
- SBOMs are driven by US EO 14028 and the EU Cyber Resilience Act; AIBOMs by the EU AI Actβs technical-documentation duties for high-risk systems.
- If you ship AI features, you need an AIBOM β an SBOM alone misses the model weights and training data that carry the real risk.
- Generate one free with the PlayCISO AIBOM tool, then diff and validate it.
Frequently asked questions
What is the difference between an SBOM and an AIBOM?
An SBOM (Software Bill of Materials) inventories the software components and dependencies in a build, each with its version and license. An AIBOM (AI Bill of Materials) extends that idea to an AI system: it includes the software of an SBOM plus every model and dataset the system is built from, each tagged with its license, version and provenance. The AIBOM captures exactly the parts an ordinary SBOM never did β the model weights and the training data.
What is an MLBOM, and is it the same as an AIBOM?
An MLBOM (Machine Learning Bill of Materials) describes the composition of a specific machine-learning model: its architecture, the datasets it was trained on, hyperparameters, and the provenance of its weights. It is narrower than an AIBOM. Think of the MLBOM as the model-level record and the AIBOM as the whole-system record that wraps the MLBOM together with the surrounding application software.
Which one does the EU AI Act require?
The EU AI Act does not use the term AIBOM, but its technical-documentation and record-keeping duties for high-risk AI systems require exactly what an AIBOM captures: the models and datasets used, their provenance, and how the system is composed. An AIBOM is the practical artifact that satisfies those duties, the way an SBOM satisfies software-transparency requirements.
Do I need all three?
Rarely all three as separate documents. If you ship software, start with an SBOM. If that software includes AI features, upgrade to an AIBOM, which subsumes the SBOM. If you train or fine-tune models, keep an MLBOM for each model artifact so you have its training-data lineage; your AIBOM can then reference those MLBOMs.